Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Sportspress MEDIUM 5.3
CVE-2024-1178

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Fix: 2.7.18+
Fix from $1,600 2024-03-05
Page Builder Sandwich MEDIUM 6.5
CVE-2024-1285

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Fix: after 5.1.0
Fix from $1,600 2024-03-05
Page Builder Sandwich MEDIUM 6.5
CVE-2024-1381

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi…

Fix: after 5.1.0
Fix from $1,600 2024-03-05
Change Memory Limit MEDIUM 5.3
CVE-2024-1093

The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic(…

Mitigation only
Fix from $1,600 2024-03-05
Android MEDIUM 6.7
CVE-2024-20032

In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-03-04
Finale MEDIUM 5.3
CVE-2024-1120

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulne…

Fix: 2.18.0 / 2.18.1+
Fix from $1,600 2024-03-01
Sirv HIGH 8.8
CVE-2024-27950

Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Fix: 7.2.1+
Fix from $1,950 2024-03-01
Airflow MEDIUM 5.9
CVE-2024-27906

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not hav…

Fix: 2.8.2+
Fix from $1,600 2024-02-29
Mattermost Server MEDIUM 6.5
CVE-2024-23493

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a …

Fix: 8.1.9 / 9.2.5+
Fix from $1,600 2024-02-29
Migration\, Backup\, Staging CRITICAL 9.1
CVE-2024-1982

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_resto…

Fix: after 0.9.68
Fix from $2,300 2024-02-29
Perfmatters HIGH 8.8
CVE-2023-47874

Missing Authorization vulnerability in Perfmatters.This issue affects Perfmatters: from n/a through 2.1.6.

Fix: 2.1.7+
Fix from $1,950 2024-02-29
Woo Czech MEDIUM 5.3
CVE-2024-1492

The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta …

Fix: 4.0.9+
Fix from $1,600 2024-02-29
Membership \& Content Restriction Paid Member Subscriptions MEDIUM 5.3
CVE-2024-1389

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthoriz…

Fix: 2.11.2+
Fix from $1,600 2024-02-29
Wp Login Lockdown MEDIUM 5.4
CVE-2024-1340

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ge…

Fix: 2.09+
Fix from $1,600 2024-02-29
Rss Aggregator By Feedzy MEDIUM 6.5
CVE-2024-1318

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized m…

Fix: after 4.4.2
Fix from $1,600 2024-02-29
Directorist MEDIUM 5.3
CVE-2024-1322

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 7.8.5+
Fix from $1,600 2024-02-29
Contact Form Builder MEDIUM 5.4
CVE-2024-1218

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of da…

Fix: 2.3.41+
Fix from $1,600 2024-02-29
Accelerated Mobile Pages MEDIUM 6.5
CVE-2024-1043

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'a…

Fix: 1.0.93.2+
Fix from $1,600 2024-02-29
Customer Reviews For Woocommerce MEDIUM 5.3
CVE-2024-1044

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…

Fix: 5.39.0+
Fix from $1,600 2024-02-29
Oliver Pos HIGH 7.3
CVE-2024-0702

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on seve…

Fix: 2.4.2.1+
Fix from $1,950 2024-02-29
Royal Elementor Addons MEDIUM 5.3
CVE-2024-0516

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on…

Fix: 1.3.88+
Fix from $1,600 2024-02-29
Anti Hacker MEDIUM 5.3
CVE-2024-1860

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized mod…

Fix: 4.52+
Fix from $1,600 2024-02-28
Wp Ecommerce MEDIUM 5.3
CVE-2024-1516

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_p…

Fix: after 3.15.1
Fix from $1,600 2024-02-28
Redirects MEDIUM 6.5
CVE-2024-1566

The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all v…

Fix: after 1.2.1
Fix from $1,600 2024-02-28
Coming Soon Page \& Maintenance Mode MEDIUM 5.3
CVE-2024-1136

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check …

Fix: 2.2.2+
Fix from $1,600 2024-02-28
Page Duplicator MEDIUM 5.3
CVE-2024-1368

The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_pa…

Fix: after 0.1.1
Fix from $1,600 2024-02-28
Woocommerce Thank You Page Customizer MEDIUM 5.4
CVE-2024-1687

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to…

Fix: after 1.1.3
Fix from $1,600 2024-02-27
Addon Library HIGH 8.8
CVE-2024-1710

The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function ac…

Fix: after 1.3.76
Fix from $1,950 2024-02-26
Admin Side Data Storage For Contact Form 7 MEDIUM 5.3
CVE-2024-1779

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Fix: after 1.1.1
Fix from $1,600 2024-02-23
Admin Side Data Storage For Contact Form 7 MEDIUM 5.3
CVE-2024-1778

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch…

Fix: after 1.1.1
Fix from $1,600 2024-02-23